Security Notice: Unauthorized Access via Third-Party Analytics Tool
RESOLVED
On 3 August 2026, an attacker exploited a zero-day vulnerability in Metabase, a third-party analytics tool we use internally, and gained read-only access for approximately 26 minutes to a data warehouse holding a copy of Checkly operational data. Our production platform, including check execution and alerting, was not accessed, and Checkly secrets remained encrypted. Values stored directly in check configurations (custom headers, cookies, query parameters, authorization headers) and hashed OTEL API keys should be considered exposed. We recommend rotating any affected credentials. Metabase has patched the vulnerability and we have investigated the impact.
Full details and remediation steps are available in our blog post: https://checklyhq.com/blog/metabase-security-incident